Hi all,
I haven't had a virus slip through in a long time, but this morning one came through 
to an alias.


* I'm running Declude 1.34 with F-prot with definitions dated 1/28/02. The version of 
Badtrans that was caught by Norton on the desktop was reported as [EMAIL PROTECTED]


* The header of the email that came through said that it was "Content-Type: 
audio/x-wav; name="S3MSONG.DOC.s c r"" (I added spaces)
In addition to Declude/F-Prot, I have Imail rules that block several file extensions, 
including .s c r


* The Declude log reported that Q file as "Virus Free [MIME: 0 0]


* My Declude virus config file SCANFILE section is setup as follows:
SCANFILE        C:\vscan\fprot\f-prot.exe /TYPE /SILENT /NOMEM /ARCHIVE /NOFLOPPY 
/NOBOOT /DUMB /REPORT=report.txt
VIRUSCODE       3
VIRUSCODE       6
VIRUSCODE       8
REPORT          Infection


It's not setup to SKIP or BAN any extensions, PRESCAN is off, BANCLSID is on, and 
DELIVERERRORS is off


1. Anyone have a clue how this got through?
2. Has anyone else seen this get through, or blocked it recently?



Jeff Lesperance
Matrix Group International, Inc.



*** Custom Web Solution and Web-Based Association Management Software.
Have you been Maxximized? http://www.matrixmaxx.net ***


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

Reply via email to